# Logins

URL: https://submitator.com/docs/api/logins

> The accounts created for your client on directories that need one: where each signs in, its email and username, whether it is ready, and the one password they all use.

The accounts created for your client on directories that need one: where each signs in, its email and username, whether it is ready, and the one password they all use. Hand them to your client, so your client owns the listings.

Logins are credentials. A read-only key gets 403 `permission_denied`, responses carry `Cache-Control: no-store`, and logins never appear in events or webhooks.

## List a project's logins

`GET https://api.submitator.com/v1/projects/{project_id}/logins`

Returns the accounts created for the project on directories that need one, by directory name, with the one password they all use. A login is ready once its account exists; until then it is being set up. Logins are credentials: a read-only key gets 403 `permission_denied`, and responses carry `Cache-Control: no-store`.

| Parameter | In | Required | What it is |
| --- | --- | --- | --- |
| `project_id` | path | Yes | The project's id. |

Response 200:

```json
{
  "object": "project_logins",
  "livemode": false,
  "project": "prj_4QzX1m9Lr2Vb7Nc8Tk3HwP",
  "password": "Kq7mZt3vRw9x!Pa2",
  "logins": [
    {
      "object": "login",
      "listing": "lst_7Hk2Qn4Rt9Vx1Bm6Cz3LdK",
      "directory": {
        "id": "dir_2Lm8Wq3Zk7Rt1Xc5Vb9NdF",
        "name": "BetaList",
        "domain_rating": 73,
        "logo_url": "https://feed.example.net/a/x1Lq7Rt.k9Zm"
      },
      "site_url": "https://betalist.com",
      "email": "founder@ledgerly.test",
      "username": null,
      "ready": true,
      "emails_count": null
    },
    {
      "object": "login",
      "listing": "lst_5Wq9Lm2Xr7Kt3Vb8Nz1HcD",
      "directory": {
        "id": "dir_6Pw3Kx9Ty2Rq7Lm1Zb5VcN",
        "name": "SaaSHub",
        "domain_rating": 61,
        "logo_url": "https://feed.example.net/a/h4Sw8Lp.q2Xn"
      },
      "site_url": "https://www.saashub.com",
      "email": "ledgerly84@login.test",
      "username": "ledgerly91",
      "ready": true,
      "emails_count": 2
    }
  ]
}
```

Typical errors: [`permission_denied`](https://submitator.com/docs/errors#permission_denied), [`not_found`](https://submitator.com/docs/errors#not_found), [`rate_limited`](https://submitator.com/docs/errors#rate_limited).

## List the emails a login received

`GET https://api.submitator.com/v1/listings/{listing_id}/emails`

Returns up to 25 emails the listing's directory sent to its login, newest first, as text with their links. Use it for a confirmation code or a password reset link. A login whose `emails_count` is `null` receives its emails at your client's own address, and this returns 404 for it.

| Parameter | In | Required | What it is |
| --- | --- | --- | --- |
| `listing_id` | path | Yes | The listing's id. |

Response 200:

```json
{
  "object": "login_emails",
  "livemode": false,
  "listing": "lst_5Wq9Lm2Xr7Kt3Vb8Nz1HcD",
  "email": "ledgerly84@login.test",
  "emails": [
    {
      "from": "SaaSHub",
      "from_email": "noreply@login.test",
      "subject": "Your sign-in code for SaaSHub",
      "received_at": "2026-10-05T11:02:00Z",
      "text": "Your code is 482913. It expires in 10 minutes.\n\nThis is a test mode sample: nothing was sent.",
      "links": []
    },
    {
      "from": "SaaSHub",
      "from_email": "noreply@login.test",
      "subject": "Confirm your email for SaaSHub",
      "received_at": "2026-10-03T14:04:00Z",
      "text": "Confirm the account you created on SaaSHub: https://login.test/saashub/confirm/9f2c4e7a1b3d5f60a8c2e4b6\n\nThis is a test mode sample: nothing was sent.",
      "links": [
        "https://login.test/saashub/confirm/9f2c4e7a1b3d5f60a8c2e4b6"
      ]
    }
  ]
}
```

Typical errors: [`permission_denied`](https://submitator.com/docs/errors#permission_denied), [`not_found`](https://submitator.com/docs/errors#not_found), [`rate_limited`](https://submitator.com/docs/errors#rate_limited).
